Apache Httpclient vulnerabilities
7 known vulnerabilities affecting apache/httpclient.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2025-27820HIGHCVSS 7.5≥ 5.4, < 5.4.32025-04-24
CVE-2025-27820 [HIGH] CWE-295 CVE-2025-27820: A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie ma
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
nvd
CVE-2020-13956MEDIUMCVSS 5.3fixed in 4.5.13≥ 5.0.0, < 5.0.32020-12-02
CVE-2020-13956 [MEDIUM] CVE-2020-13956: Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority co
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
nvd
CVE-2013-4366CRITICALCVSS 9.8v4.32017-10-30
CVE-2013-4366 [CRITICAL] CWE-20 CVE-2013-4366: http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
nvd
CVE-2015-5262MEDIUMCVSS 4.3≥ 4.3, ≤ 4.3.52015-10-27
CVE-2015-5262 [MEDIUM] CWE-399 CVE-2015-5262: http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignor
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
nvd
CVE-2014-3577MEDIUMCVSS 5.8≥ 4.0, ≤ 4.3.42014-08-21
CVE-2014-3577 [MEDIUM] CVE-2014-3577: org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpA
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string
nvd
CVE-2012-5783MEDIUMCVSS 5.8v3.12012-11-04
CVE-2012-5783 [MEDIUM] CWE-295 CVE-2012-5783: Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK a
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid ce
nvd
CVE-2011-1498MEDIUMCVSS 4.3v4.0v4.0.1+1 more2011-07-07
CVE-2011-1498 [MEDIUM] CWE-200 CVE-2011-1498: Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy
Apache HttpClient 4.x before 4.1.1 in Apache HttpComponents, when used with an authenticating proxy server, sends the Proxy-Authorization header to the origin server, which allows remote web servers to obtain sensitive information by logging this header.
nvd